s90

Non-profits · South Orange County

The people you serve trust you with their health, their information and their wellbeing. Does your IT earn that trust, or just assume it?

Case notes and intake, donor records and grant reports, handled from the office, in the field and through the overnight shift.

What your programs and payments require
A staff member works at a computer behind the reception counter of a small community services office.

s90 manages IT for social services and health-related non-profits in south Orange County. We run your systems end to end, plan the switch around your programs and grant deadlines, and send a Technology Posture Report every quarter that answers funders, the county and insurers, plus a Compliance Posture Report for HIPAA or PCI DSS when they apply.

Three staff members review a printed page together at a shared table in a small community services office.

Does this sound familiar?

Case notes, health information and donor records on every laptop and phone, including the ones staff bring from home, software that renews whether anyone uses it or not, and staff trying AI tools nobody has vetted. Someone handles your IT, but when a funder, the county or your board asks whether it's secure, whether the budget is going to the right things, or where information about the people you serve is going, the honest answer is a guess.

I'm trusting it on faith.
I couldn't show it if someone asked.

Most non-profits have someone handling their IT. Tickets come in, tickets get closed, and nobody asks whether the organization is safer, spending well or able to show its work. Having someone handle your IT isn't the same as having your IT managed.

Proof before a funder asks

Asking your provider for proof is awkward. You shouldn't have to.

The people you serve trust you with their health, their personal information and their wellbeing, and your donors and funders trust you to protect it. Your reputation rests on compassion, discretion and good stewardship, so your IT should be able to prove it. We hold ourselves to the standard you hold for the people you serve: ready when a grant deadline or your year-end giving season won't move, keeping you ahead of what's changing for non-profits, and working alongside you toward the mission you're building.

Verified

One line of evidence

2-step sign-in on every account

What we checked
Whether every staff account requires a second step to sign in
What we found
38 of 38 accounts
Why it matters
A stolen password alone cannot open your email or documents
Date checked
7 Oct 2026 · CIS 6.3, 6.4 · NIST CSF PR.AA-03 · Weight 5

The framework references are for your regulators and auditors. You don't need to read them.

Get the sample Posture Report by email

Planned around the people you serve

Three steps, planned around your programs and grant deadlines.

If it's in the table below, we already support it, including the county systems your programs report to. Your team is here for the people you serve, not for IT, so we coordinate the switch with your previous provider and your software vendors, and your staff stay focused on the mission.

01 · Baseline

See where you stand

Before anything changes, we review your setup and give you your Baseline Posture Score, a score out of 100 taken before we take over. You see where you stand, and exactly what we're taking on.

02 · Handoff

Seamless switch

We coordinate with your current provider and cut over when it's not disruptive. We schedule your handoff around the dates that you can't move.

03 · Ownership

We own it from here

Support, security, maintenance and planning are ours. Every quarter your Technology Posture Report arrives, and your Technology Adviser walks you through it: what changed, what it means for you, and what we recommend next.

The platforms your team relies on

Donor and fundraising

Bloomerang,Blackbaud Raiser's Edge NXT,DonorPerfect,Givebutter

Accounting and bookkeeping

QuickBooks Online,Sage Intacct

Finance

Blackbaud Financial Edge NXT

Payroll

Paylocity,Gusto

Behavioral health records

Exym,Welligent,Qualifacts Credible,Kipu,SimplePractice

Case management

Bonterra Apricot,CaseWorthy,Eccovia ClientTrack

Senior services

WellSky Aging and Disability,ServTracker

County and state systems

OC Health Care Agency IRIS,Orange County HMIS,DHCS PAVE

Volunteer and board

Volgistics,SignUpGenius,Boardable

Grants

Instrumentl,Candid,GrantHub

Everyday

Microsoft 365,Google Workspace,Mailchimp,Canva,DocuSign,Zoom,Adobe Acrobat

Before you switch

You get a dated plan before anything changes, built around your grant deadlines, events and the programs that run every day, including overnight. Tools are swapped one at a time, and your staff are trained on anything new before they need it. It's designed so the people you serve never lose access to the help they count on.

What's at stake for the people you serve

What it costs when nobody owns your organization's IT.

The slow leak

Donor and grant dollars go to licenses no one uses, aging equipment and tools no one is watching, while staff put information about the people they serve into AI tools with no guardrails and do their work on personal laptops and phones to save the organization money.

The sudden hit

Ransomware locks the case records staff need for the day's appointments; a breach exposes the personal information of the people who trusted the organization with it; one bad email redirects a vendor payment or a grant disbursement.

When someone owns your IT

Every device, license and login accounted for, including the ones staff bring from home. Donor and grant dollars going to tools someone is actually using. Recovery plans that have actually been tested, so the day's appointments never depend on luck. Support around the clock, in your office and through self-service for everyday requests. And proof in hand that's never more than three months old, so when a funder, the county or your insurer asks, the answer is already on your desk. You know your IT is taken care of.

A staff member works at a computer behind the reception counter of a small community services office.

What your programs and payments require

For organizations that need to prove it

If your organization delivers health services, the health information you keep comes with federal rules for protecting it, and for what happens if it's ever exposed (HIPAA). If you accept donations by card, your payment processor requires you to protect card data to an industry standard (PCI DSS). Beyond those, a recognized framework, NIST CSF 2.0 or CIS Controls, is how you answer the questions funders, the county and insurers ask, and we'll help you choose the one that fits. From there, we provide current evidence that your controls are in place and working. The person in charge of compliance at your organization decides whether you're compliant.

Bundle discounts available.

What's at stake

A funder, the county or a cyber insurer asking how you protect information when you can't show it, a county contract renewal with security requirements you can't prove you meet, a lost laptop holding health records that turns into required notifications and a federal investigation, or a payment processor asking for a PCI DSS attestation you don't have.

s90

One question to ask yourself

Does your IT provider show you proof without you having to ask?

Up to$500,000Cyber WarrantyBacked by Cork Inc.

In 30 minutes, we talk through your setup and you leave knowing which plan fits.

Book a call

See exactly what you'd receive each quarter, by email.

Get the sample Posture Report by email